Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228561 7.5 危険 w2b - W2B phpDatingClub の website.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3179 2012-12-20 18:52 2008-07-15 Show GitHub Exploit DB Packet Storm
228562 7.5 危険 webxell - WebXell Editor の upload_pictures.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-3178 2012-12-20 18:52 2008-07-15 Show GitHub Exploit DB Packet Storm
228563 5 警告 ソフォス - Linux および Unix 上で稼動している Sophos ウィルス検出エンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-16
環境設定
CVE-2008-3177 2012-12-20 18:52 2008-07-15 Show GitHub Exploit DB Packet Storm
228564 6.8 警告 regretless - DodosMail の dodosmail.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3163 2012-12-20 18:52 2008-07-14 Show GitHub Exploit DB Packet Storm
228565 7.5 危険 webblizzard - WebBlizzard CMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3154 2012-12-20 18:52 2008-07-11 Show GitHub Exploit DB Packet Storm
228566 7.5 危険 tritoncms - Triton CMS Pro における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3153 2012-12-20 18:52 2008-07-11 Show GitHub Exploit DB Packet Storm
228567 7.5 危険 warpspeed
PHPNUKE
- PHP-Nuke 用の 4ndvddb モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3151 2012-12-20 18:52 2008-07-11 Show GitHub Exploit DB Packet Storm
228568 4.7 警告 wefi - WeFi における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-3147 2012-12-20 18:52 2008-07-11 Show GitHub Exploit DB Packet Storm
228569 7.8 危険 secretwars - Soldner Secret Wars におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2008-3135 2012-12-20 18:52 2008-07-10 Show GitHub Exploit DB Packet Storm
228570 6.8 警告 Powie - pSys の chatbox.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3131 2012-12-20 18:52 2008-07-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208911 8.8 HIGH
Network
simple-log_project simple-log Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_add_member". CWE-352
 Origin Validation Error
CVE-2020-18265 2024-11-21 14:08 2021-06-8 Show GitHub Exploit DB Packet Storm
208912 8.8 HIGH
Network
simple-log_project simple-log Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member". CWE-352
 Origin Validation Error
CVE-2020-18264 2024-11-21 14:08 2021-06-8 Show GitHub Exploit DB Packet Storm
208913 8.8 HIGH
Network
libjpeg-turbo libjpeg-turbo Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial… CWE-787
 Out-of-bounds Write
CVE-2020-17541 2024-11-21 14:08 2021-06-2 Show GitHub Exploit DB Packet Storm
208914 7.5 HIGH
Network
gnu gama A NULL-pointer deference issue was discovered in GNU_gama::set() in ellipsoid.h in Gama 2.04 which can lead to a denial of service (DOS) via segment faults caused by crafted inputs. CWE-476
 NULL Pointer Dereference
CVE-2020-18395 2024-11-21 14:08 2021-05-29 Show GitHub Exploit DB Packet Storm
208915 5.5 MEDIUM
Local
cesanta mjs Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file. CWE-674
 Uncontrolled Recursion
CVE-2020-18392 2024-11-21 14:08 2021-05-29 Show GitHub Exploit DB Packet Storm
208916 4.8 MEDIUM
Network
phpmywind phpmywind Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_switchshow" of component " /admin/web_config.php". CWE-79
Cross-site Scripting
CVE-2020-18230 2024-11-21 14:08 2021-05-28 Show GitHub Exploit DB Packet Storm
208917 4.8 MEDIUM
Network
phpmywind phpmywind Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote attackers to execute arbitrary code by injecting scripts into the parameter "$cfg_copyright" of component " /admin/web_config.php". CWE-79
Cross-site Scripting
CVE-2020-18229 2024-11-21 14:08 2021-05-28 Show GitHub Exploit DB Packet Storm
208918 7.4 HIGH
Network
apache fineract Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a man in the middle attack could be successful. NVD-CWE-Other
CVE-2020-17514 2024-11-21 14:08 2021-05-27 Show GitHub Exploit DB Packet Storm
208919 6.1 MEDIUM
Network
typora typora Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula. CWE-79
Cross-site Scripting
CVE-2020-18221 2024-11-21 14:08 2021-05-27 Show GitHub Exploit DB Packet Storm
208920 7.5 HIGH
Network
html-js doracms Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted … CWE-326
Inadequate Encryption Strength
CVE-2020-18220 2024-11-21 14:08 2021-05-21 Show GitHub Exploit DB Packet Storm